BitMaskOS: A Capability-Native Operating System Abstraction for AI Service Meshes

Fuente: Zenodo
Guardado en:
Detalles Bibliográficos
Autor principal: Sharma, Anil
Formato: Recurso digital
Publicado: Zenodo 2026
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866901167970189312
author Sharma, Anil
author_facet Sharma, Anil
contents ANKR Research Papers #85. BitMaskOS (BMOS) is an operating system abstraction for AI service meshes, replacing probabilistic capability discovery with O(1) bitwise proof. Drawing on classical OS primitives — process descriptors, capability tables, syscall gates, fault isolation, and init systems — BMOS maps each to a bitmask equivalent: codex.json (process descriptor), AnkrCodex (process table), trust_mask (process capabilities), perm_mask (thread capabilities), KAVACH (kernel syscall gate), and gate valve (fault isolation without restart). The paper introduces BMOS-Authorize: a service-level authorization endpoint that checks capability intersection at call time, completing the OS analogy. KAVACH handles agent-level (thread) enforcement; BMOS-Authorize handles service-level (process) enforcement. Two layers, same primitive: bitwise AND. Validated across 236 ANKR services with declared trust_masks. v2 (2026-04-30): BMOS-Authorize shipped. Section 8.3 added with live implementation evidence: measured p50 latency 8-11us across 236-service mesh, full audit log, codex.json protocol declaration (protocol: bitmask-os-v1). Status updated Pending to Live in Section 8.1.
format Recurso digital
id zenodo_https___doi_org_10_5281_zenodo_19937211
institution Zenodo
language
publishDate 2026
publisher Zenodo
record_format zenodo
spellingShingle BitMaskOS: A Capability-Native Operating System Abstraction for AI Service Meshes
Sharma, Anil
bitmask operating system
capability-native architecture
AI service mesh
KAVACH
trust_mask
perm_mask
BMOS-Authorize
O(1) authorization
gate valve
microservice security
agent capability enforcement
AnkrCodex
zero hallucination
ANKR Research Papers #85. BitMaskOS (BMOS) is an operating system abstraction for AI service meshes, replacing probabilistic capability discovery with O(1) bitwise proof. Drawing on classical OS primitives — process descriptors, capability tables, syscall gates, fault isolation, and init systems — BMOS maps each to a bitmask equivalent: codex.json (process descriptor), AnkrCodex (process table), trust_mask (process capabilities), perm_mask (thread capabilities), KAVACH (kernel syscall gate), and gate valve (fault isolation without restart). The paper introduces BMOS-Authorize: a service-level authorization endpoint that checks capability intersection at call time, completing the OS analogy. KAVACH handles agent-level (thread) enforcement; BMOS-Authorize handles service-level (process) enforcement. Two layers, same primitive: bitwise AND. Validated across 236 ANKR services with declared trust_masks. v2 (2026-04-30): BMOS-Authorize shipped. Section 8.3 added with live implementation evidence: measured p50 latency 8-11us across 236-service mesh, full audit log, codex.json protocol declaration (protocol: bitmask-os-v1). Status updated Pending to Live in Section 8.1.
title BitMaskOS: A Capability-Native Operating System Abstraction for AI Service Meshes
topic bitmask operating system
capability-native architecture
AI service mesh
KAVACH
trust_mask
perm_mask
BMOS-Authorize
O(1) authorization
gate valve
microservice security
agent capability enforcement
AnkrCodex
zero hallucination
url https://doi.org/10.5281/zenodo.19937211